Guide
ChatGPT in medicine: the clear-eyed guide
90% of French health professionals already use AI, mostly ChatGPT. What it genuinely does well for a physician, where medical confidentiality draws the line, and what ChatGPT Health actually changes.
Published July 18, 2026
The question is no longer whether physicians use ChatGPT. According to the ACSEL 2025 barometer, 90% of French health professionals say they use AI, 84% of them via ChatGPT. The real question is what you can safely hand it. Short answer: ChatGPT is a useful writing assistant for anything that contains no patient data. Beyond that, medical confidentiality is on the line.
What ChatGPT does well for a physician
Three uses hold up, provided no patient data ever goes in:
- Literature work: scoping a question, summarising a paper, comparing guidelines. Check every reference: the tool still invents some, with perfect confidence.
- Rewriting: turning a report into something a patient can read, adjusting register, translating a document.
- Administrative drafting: template letters, internal practice protocols, information notes, replies to payers - on generic or genuinely anonymised content.
Used that way, the tool gives time back. Everything turns on the moment a patient file enters the input box.
Where the line is: patient data
French law predates AI.
- Medical confidentiality binds every physician and covers everything learned in the course of practice: article R.4127-4 of the public health code. Breaching it is a criminal offence punishable by one year in prison and a 15,000-euro fine (article 226-13 of the penal code).
- Health data falls under the special categories of article 9 GDPR: processing prohibited by default, allowed by exception.
- OpenAI is not an HDS-certified host, the French certification required to host health data on behalf of third parties. Conversations land on OpenAI's servers, under US law: the Cloud Act lets US authorities reach the data of an American company, wherever it is stored.
Pasting a named consultation report into ChatGPT is therefore not a grey area: it is a transmission of confidential data to an unauthorised third party.
The movement reaches well beyond medical practices. In April 2026, a viral thread on X described French people pasting blood work, MRI reports and discharge summaries into ChatGPT every day without anonymising anything: citizens had built "the largest medical record in France" on their own, on OpenAI's servers.
Does ChatGPT Health change the picture?
OpenAI launched ChatGPT Health in January 2026: a dedicated space for health conversations with, per OpenAI, reinforced encryption and conversations that are not used to train its models. Real progress for the general public.
What does not change: the data is still hosted by OpenAI, hence under US jurisdiction; the tool is still not HDS-certified; and a consumer space does not make OpenAI your practice's GDPR processor within the meaning of article 28. For a physician, the line sits exactly where it did.
Control over health data is broader than the ChatGPT case anyway. On 8 July 2026, Doctolib emailed its users to announce the opening in August of an AI research lab drawing on their health data, included in the project by default unless users object through a dedicated form. The episode is documented by franceinfo and La Voix du Nord.
What the institutions say
No French institution bans these tools. All of them set conditions.
- On 30 October 2025 the HAS published its first keys for using generative AI in healthcare, built around the A.V.E.C. framework: learn how the tools work, verify every generated output, assess their fit over time, communicate with your ecosystem.
- In March 2026 the HAS and the CNIL put out for consultation a draft joint guide on the sound use of AI systems in care settings: legal framework and good practice, from acquiring a tool to decommissioning it.
- The French medical council maintains a doctrine on data, algorithms and AI with one constant thread: medical decisions belong to the physician, not to the machine.
Five rules for safe use
- Never any identifying data: no name, no date of birth, no social security number, no address.
- Anonymise for real: also remove what re-identifies by cross-reference (occupation, town, rare condition, precise dates). If the case is still recognisable, it is not anonymous.
- Reread everything: no generated content goes into a file or to a colleague without sign-off.
- Tell the patient when AI contributed to a document or a step that concerns them.
- Keep a trail: which tool, on which file, when.
Or own your own
These rules govern a tool that belongs to someone else and runs under someone else's law. The other path: your own instance, installed within the practice's walls or on HDS-certified infrastructure in France, with an audit log and answers that cite their sources. Medical confidentiality stops being a list of prohibitions to police: your data no longer goes to a third party under another jurisdiction. That is what we build for practices and care organisations. A useful starting point: what HDS certification covers - and what it does not.
Frequently asked questions
Is ChatGPT reliable in medicine?
As a drafting and summarising assistant, yes, with proofreading. As a medical source, no: it is not a medical device, it is not designed for diagnostic support, and it still produces invented references. That is the V in the HAS's A.V.E.C. framework: every generated output gets verified before use.
What is the risk of signing up for ChatGPT?
For generic use, none in particular. The risk lies in what you feed it: the consumer version keeps conversations by default and may use them to train models (a setting lets you refuse), all hosted in the United States, outside the HDS framework. The real risk, for a clinician, is slipping on a busy day from a template letter to a named consultation report.
Can you put patient data into ChatGPT?
Legally, no: medical confidentiality (articles R.4127-4 of the public health code and 226-13 of the penal code), health data under article 9 GDPR, neither HDS certification nor a processing contract. In practice, real anonymisation is more demanding than it looks: a clinical case often remains re-identifiable by cross-reference. The safe rule: any doubt about anonymity, and the data stays inside the practice.
Will AI replace doctors?
No. Both the texts and the practice converge on augmentation: AI drafts, summarises, searches and cites its sources; the physician keeps clinical judgment, the patient relationship and the liability. The useful question is less about replacement than about the infrastructure, and the jurisdiction, under which the AI assisting you will run.